Apache Thrift
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 29
Severity across 28 analyzed records
en
Severity across 28 analyzed records
Verify to analyze this security profile
As of 09/14/2026, within CyStack's analyzed data, Apache Thrift has 15 security vulnerabilities published in the last 90 days. Of these, 11 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache Thrift and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-66053Apache Thrift: Python TSSLSocket Hostname Matcher Import | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityMedium |
CVE-2026-58662Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-58389Apache Thrift: Rust binary protocol non-strict path missing string size limit | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-58023Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityMedium |
CVE-2026-55971Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityCritical |
CVE-2026-55970Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityMedium |
CVE-2026-55969Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-55968Apache Thrift: Node.js quadratic-time DoS in server receive transports | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-49158Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-48586Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-48145Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-48144Apache Thrift: c_glib TLS Client Missing Hostname Verification | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityCritical |
CVE-2026-45112Apache Thrift: Unbounded Read Leading to Denial of Service | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityMedium |
CVE-2026-43871Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-41608Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityHigh |
CVE-2026-43868Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern | Exploitation statusNot known exploited | FixYes | Published05/05/2026 | SeverityHigh |
CVE-2026-43870Apache Thrift: Node.js web_server.js multi-vulnerability | Exploitation statusNot known exploited | FixYes | Published05/05/2026 | SeverityHigh |
CVE-2026-43869Apache Thrift: TSSLTransportFactory.java hostname verification | Exploitation statusNot known exploited | FixYes | Published05/05/2026 | SeverityHigh |
CVE-2026-41636Apache Thrift: Node.js skip() recursion | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityHigh |
CVE-2026-41607Apache Thrift: C++ JSON OOB read | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityCritical |
CVE-2026-41606Apache Thrift: c_glib dispatch stack overflow | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityHigh |
CVE-2026-41605Apache Thrift: Swift Compact Protocol integer overflow | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityHigh |
CVE-2026-41604Apache Thrift: Swift Range crash in skip() | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityHigh |
CVE-2026-41603 | Exploitation statusNot confirmed | FixNot confirmed | Published04/28/2026 | SeverityUnknown |
CVE-2026-41602Apache Thrift: Go TFramedTransport uint32 overflow | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityHigh |
CVE-2025-48431Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityHigh |
CVE-2018-1320 | Exploitation statusNot confirmed | FixNot confirmed | Published01/07/2019 | SeverityUnknown |
CVE-2018-11798 | Exploitation statusNot confirmed | FixNot confirmed | Published01/07/2019 | SeverityUnknown |
CVE-2016-5397 | Exploitation statusNot confirmed | FixYes | Published02/12/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan